1. Who we are
WITAL.AI (“WITAL”, “we”, “us”) is operated by WooSee Limited, a company registered in England and Wales (company number 14364528). Our registered address is 71–75 Shelton Street, Covent Garden, London WC2H 9JQ, United Kingdom. We are registered with the UK Information Commissioner’s Office under registration number ZB532687.
We are the data controller for the personal data described in this policy. You can contact us at solo@woosee.pro for any privacy-related matter.
2. Scope
This policy covers WITAL.AI across all delivery channels: the web application at wital.ai, the iOS app (“AI Weather (WITAL)” on the App Store), and the Android app on Google Play. WITAL is a weather service that uses AI to generate plain-language forecasts and to answer weather questions.
3. What data we collect
Data you provide
| Data | When | Purpose |
|---|---|---|
| Email address | When you create an account | Account identity, sign-in codes, account notices |
| Display name (optional) | If you set one | Personalisation in the app |
| Passkey public key, identifier, signature counter, transports, authenticator model code, and any nickname you set | When you register a passkey | Signing you in. The private key never leaves your device and we never receive it. |
| Current location and preferences | When you set them | Producing your forecast. Your saved-locations list and recent searches remain on your device and are not sent to us. |
| Notification schedules (time, language, location) | When you enable notifications | Delivering scheduled forecasts |
| Chat messages | When you use weather chat, signed in or not | Answering you, and continuing a conversation across sessions. Linked to your account when signed in; when signed out, grouped by a short one-way hash of your IP address. You can switch chat storage off in Settings. |
We do not use passwords. Sign-in is by passkey or by a one-time code sent to your email address. We previously offered password and social sign-in; both have been removed, along with the stored password hashes and linked social accounts.
Data collected automatically
| Data | Source | Purpose |
|---|---|---|
| Device location (approximate or precise) | Your device, only when you ask for a current-location forecast | Producing that forecast. Coordinates are used for the request only and are not written to our database. They are passed in the request URL, so they do appear in server access logs for the retention stated in section 7. |
| Push notification token (APNs or FCM) | Your device, only if you enable push notifications | Delivering scheduled notifications |
| Internal user ID | Generated when you create an account | Linking your records, and identifying you to our subscription provider |
| Access logs (IP, user-agent, request path, timestamp) | Our servers | Security, abuse prevention, operational monitoring |
| Analytics and advertising cookies (website only) | Google Analytics and Google AdSense, stored only after you accept in the cookie banner | Audience measurement and advertising on the website |
Data we do not collect
We never receive your card, bank or other payment details — the App Store and Google Play take payment and do not pass those details to us. We also do not collect health or fitness data, photos or videos, audio, files, calendar entries, contacts, or your web browsing history.
4. How we use your data
- Service delivery — producing forecasts, answering chat, delivering notifications you opted into, keeping you signed in.
- Subscriptions — determining whether WITAL Pro is active on your account.
- Personalisation — saved locations and preferences.
- Advertising and measurement on the website — only with your consent.
- Security and abuse prevention — rate limiting, unusual sign-in detection, audit logs.
- Service improvement — diagnostics and aggregated usage metrics.
- Legal compliance — responding to lawful requests.
5. Subscriptions and payment
WITAL Pro is sold as an auto-renewing subscription through the App Store (Apple) and Google Play (Google). Those stores process the payment under their own privacy policies; no card or financial information reaches WITAL.
We use RevenueCat, Inc. (United States) to determine subscription status. RevenueCat receives your internal WITAL user ID and the store’s purchase information, and returns whether an entitlement is active and when it expires. It does not receive your email address or name.
We store against your account whether Pro is active and until when, plus a record of subscription events (purchase, renewal, cancellation, refund) so that support questions can be answered from data. Each record retains what the provider sent us for that event, which typically includes the product, the price and currency, your country, the subscription period type, and the store's transaction identifiers. Deleting your account deletes these records; Apple, Google and RevenueCat retain their own.
6. Third parties we share data with
We share data only with the providers needed to run WITAL, and only the minimum they need. We do not sell your data, and we do not share it with data brokers or marketing companies.
| Provider | Data shared | Purpose |
|---|---|---|
| Google LLC (Gemini) | For chat, the text of your conversation; for forecasts, weather data and the location only | Generating chat replies and forecast summaries |
| Amazon Web Services (London, eu-west-2) | All personal data listed above, as our cloud host | Hosting, database, email delivery (SES), content delivery (CloudFront), interface translation (Amazon Translate) |
| RevenueCat, Inc. | Internal user ID, store purchase data | Subscription status |
| Apple Inc. | Purchase and subscription data; APNs device token and notification payload | Selling the subscription; delivering iOS push notifications |
| Google (Play, Firebase Cloud Messaging) | Purchase and subscription data; FCM device token and notification payload | Selling the subscription; delivering Android push notifications |
| Google Analytics and Google AdSense | IP address and page requests when the website loads their scripts; cookie identifiers and advertising signals only after you consent — website only, never in the apps | Audience measurement and advertising |
| Telegram FZ-LLC | Telegram chat ID, notification content — only if you connect Telegram | Delivering notifications via Telegram |
A note about chat. Because chat replies are generated by Google Gemini, anything you type into chat is sent to Google. Please do not enter personal details there that you would not want processed by a third party.
A note about forecast text. Forecast summaries are produced from weather data and a place name, with no personal identifiers. Gemini is the default model; a request may instead be served by Amazon Bedrock, OpenAI or OpenRouter. Because no personal data is included, the choice of model does not change what is disclosed about you.
7. Data retention
| Data | Retention |
|---|---|
| Account data (email, name, preferences, saved locations, devices, schedules) | Until you delete your account |
| Chat conversations and messages | Signed in: until you delete your account, or until you delete the conversation. Signed out: 30 days, then removed automatically. Not stored at all if you switch chat storage off. |
| Subscription records | Until you delete your account |
| One-time sign-in codes and short-lived security records | Minutes to hours; swept automatically |
| Query-time location (lat/long) | Not stored |
| Push notification tokens | Until notifications are disabled, the token becomes invalid, or account deletion |
| Server and application logs | Up to 30 days (web-server access logs are rotated after 10). We do not currently enable CDN access logging, so no CDN log of your requests is retained. |
| Email opt-out (suppression) list | Retained for as long as we send email, because its purpose is to ensure we never contact you again. We will remove your entry on request, which also removes the suppression. |
| Encrypted database backups | 35 days |
8. Account deletion
You can delete your account at any time from Settings → Delete Account, or by visiting our account deletion page. Deletion removes your profile, passkeys, preferences, devices, notification schedules, chat history and subscription records. Your saved-locations list lives on your device, so clear it there if you want it gone. Retained items are limited to the email opt-out list, short-lived access logs, and backups that age out per the schedule above.
Deleting your account does not cancel an active subscription. Subscriptions are managed by the App Store or Google Play — cancel there, or billing continues.
9. Staff access
A small number of administrators can view account records and, for support and abuse investigation, individual chat conversations. Administrator sign-in requires a passkey, and administrator actions are recorded in an access log.
10. Your rights
Under the UK GDPR and the EU GDPR, you have the right to:
- Access the personal data we hold about you
- Rectify inaccurate or incomplete data
- Erase your data (“right to be forgotten”)
- Restrict or object to our processing
- Portability (receive your data in a machine-readable format)
- Withdraw consent at any time (for processing based on consent)
- Complain to a supervisory authority — in the UK, the Information Commissioner’s Office
To exercise any of these rights, email us at solo@woosee.pro. We respond within one month.
11. Legal bases for processing
- Contract — running your account, producing forecasts, providing a subscription you paid for.
- Consent — push notifications, precise location access, analytics and advertising cookies, optional Telegram integration.
- Legitimate interests — security, fraud prevention, diagnostics, preventing abuse of our infrastructure.
- Legal obligation — responding to valid legal requests.
12. Security
- All data in transit is encrypted with TLS 1.2+.
- Database storage is encrypted at rest (AWS-managed keys), as are backups.
- Secrets are held in AWS Systems Manager Parameter Store as encrypted SecureStrings.
- Sign-in uses passkeys or emailed one-time codes — there are no passwords to steal, and we hold no password hashes.
- Access to production systems uses least-privilege IAM roles and is logged.
- A Web Application Firewall protects our CloudFront distribution against common attacks.
13. Children’s privacy
WITAL is not directed at children under the age of 16. We do not knowingly collect personal data from anyone under 16. If you believe a child has provided us data, contact solo@woosee.pro and we will delete it.
14. International transfers
Our primary infrastructure is hosted in the United Kingdom (AWS London, eu-west-2). Several processors are outside the UK and EEA: Google (Gemini, Analytics, AdSense, Firebase Cloud Messaging), RevenueCat and Apple process data in the United States, and Telegram operates globally. Those transfers rely on the UK International Data Transfer Addendum and Standard Contractual Clauses, and on the EU–US Data Privacy Framework where the processor is certified under it.
15. Automated decision-making
Forecast text and chat replies are generated automatically, but they do not have legal or similarly significant effects on you, so this is not “automated decision-making” in the GDPR Article 22 sense.
16. Cookies and local storage
The WITAL website uses browser local storage — not cookies — to hold your session token and preferences. Local storage is not transmitted to third parties.
The website also loads Google Analytics and Google AdSense. Their scripts load with the page, but they start in a consent-denied state (Google Consent Mode): until you accept in the cookie banner, no analytics or advertising cookies are stored, no advertising identifiers are shared, and ads are not personalised. Accepting grants only the categories you choose — analytics and advertising are separate toggles — and you can change your mind at any time from the cookie settings link. Declining or dismissing the banner leaves everything denied.
Neither script is loaded inside the iOS and Android apps. Those apps do not currently serve advertising and do not use an advertising identifier.
17. Changes to this policy
We may update this policy to reflect changes in our service or legal requirements. The “Last updated” date at the top always reflects the latest version. Material changes are announced in-app or by email to registered users.
18. Contact
Privacy questions, requests, or complaints:
WooSee Limited
71–75 Shelton Street, Covent Garden
London WC2H 9JQ, United Kingdom
Email: solo@woosee.pro
ICO registration: ZB532687